Skip to content

Security: nth-bailey/PolyXML

SECURITY.md

Security Policy

Supported Versions

Security updates and patches are provided for the latest releases:

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in PolyXML (such as memory safety bugs, buffer overflows, unbounded memory allocations, or XML entity / billion-laughs vulnerabilities), please do NOT disclose it publicly.

Instead, report security issues via:

  1. GitHub Security Advisories (Preferred):

    • Visit the Security tab on GitHub and click "Report a vulnerability".
  2. Email:

What to Include

  • A detailed description of the vulnerability.
  • A minimal XML payload and code snippet reproducing the problem.
  • Impact assessment and suggested mitigations, if any.

Response Timeline

  • Initial Response: Within 48 hours.
  • Triage & Patching: Within 5 business days.
  • Public advisories and patched releases will be coordinated responsibly.

There aren't any published security advisories